Set Up Client Certificate Template Settings for NPS

In Cloudpath, certificate templates are used to generate certificates.
A template defines the properties embedded into a certificate when it is issued. Some properties are static and remain the same for every certificate. Other properties are calculated or use variables, allowing them to differ per certificate, based on user and device.

To set up a client certificate template using an onboard CA, perform the following steps:

  1. From the Cloudpath left menu, select Certificate Authority > Manage Templates.
  2. Click Add Template to create a new certificate template.
  3. Choose Use an onboard certificate authority and select the onboard CA you created in the previous section.
  4. Select Client Certificates.
    screen below updated for 5.8

    Create Client Certificate Template

  5. Select or enter a Username Decoration. The decoration of the username within the certificate allows RADIUS policies to be applied appropriately.
  6. Grant access for the appropriate amount of time.
    For example, you might have client certificate template for a guest user that is valid for one, or a few days, another for a contractor that is valid for 6 months, and one for employees that is good for a year.
    Tip: To configure pattern attributes, certificate strength, and EKUs, check the Configure Advanced Options box before you click Next. For more information about the advanced options, refer to Client Certificate Template Advanced Options.
  7. Select any email notifications to be sent to the user related to the lifecycle of the certificate.
    Additional certificate notifications can be configured after the template is created.
  8. slight change to wording for CP 5.8
    After the template has been created, you can assign RADIUS attribute policies from within the "RADIUS Policies" tab. For more information, refer to Adding RADIUS Policies to the NPS Certificate Template.
    Note: By default, this certificate template will be honored for RADIUS authentications.